Cybercriminals are increasingly targeting identity credentials rather than exploiting software vulnerabilities, fueling a thriving underground market for stolen usernames, passwords, tokens, and access rights. This so-called 'identity economy' has become a central pillar of the cybercrime ecosystem, with credentials being traded much like commodities on illicit marketplaces. Financial services and healthcare organizations remain prime targets, but the threat is universal, as evidenced by a 2023 study indicating that 95% of enterprises experienced some form of identity fraud. The financial impact is significant, with banks losing an average of $310,000 per incident and high-profile breaches, such as the $1.5 billion theft from a cryptocurrency exchange by North Korean hackers, underscoring the scale of the problem. Attackers employ a mix of traditional and modern techniques, including phishing, man-in-the-middle attacks, session hijacking, and social engineering, with AI now making phishing attempts more convincing and attacks more efficient. The rise of AI has supercharged these traditional attacks, enabling threat actors to accelerate reconnaissance and discovery phases by up to tenfold. AI is also being weaponized in new ways, such as compromising organizations' own AI instances to exfiltrate sensitive data or subvert security defenses, a tactic likened to 'living-off-the-land' but with AI agents. The cybercrime-as-a-service model further lowers the barrier to entry, allowing even less sophisticated actors to launch credential stuffing, fraudulent registration, and synthetic identity attacks at scale. To counter these evolving threats, experts emphasize the need for robust identity controls, particularly for managing access by both human users and AI agents. Industry leaders advocate for open standards, such as the draft Cross App Access extension to OAuth, which aims to provide centralized, standardized authorization for AI-driven and app-to-app interactions. The IPSIE working group and protocols like MCP and A2A are also working to establish consistent identity security profiles and authentication frameworks to safely manage AI agents' access and communication. With quantum computing on the horizon, the long-term value of stolen credentials is expected to rise, as encrypted data from past breaches could eventually be decrypted, turning old compromises into renewed threats. Multi-factor authentication (MFA) remains a critical defense, but attackers are adapting with tactics like MFA fatigue, where users are bombarded with prompts until they approve access. Insiders continue to pose risks, and the combination of human error and advanced AI-driven attacks makes comprehensive identity security more urgent than ever. The consensus among security professionals is that industry alignment on open standards and the implementation of strict access controls are essential to securing the future of digital identity in an AI-driven threat landscape.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.